IAM / IAM-01
アイデンティティライフサイクルとロール管理
各人が適切なタイミングで、適切な期間、適切な権限を確実に取得できるように、アカウントの作成、変更、削除を管理すること。.

役立つとき
的確な回答
定義されたニーズに対して.
IT, HR or business owners; slow onboarding, incomplete offboarding or accumulated access after role changes.
適用範囲と成果物
このエンゲージメントの対象範囲.
スコープ
- Authoritative identity source
- business roles and approvals
- automate or formalise joiner, mover and leaver processes
成果物
- Role matrix
- included processes and connectors
- lifecycle tests and operating guide
検収証拠
A test user is created, moved and removed; resulting access matches approved rules.
配達
仕事の進め方.
アプローチ
IDとアプリケーションの洗い出し; ロックとポリシーの定義; 1つのグループでパイロット実施; 許可・拒否・リカバリ経路のテスト; 展開と引き渡し。.
前提条件と責任
カスタマー:アプリケーションオーナー、人事、管理者、パイロットグループ、および緊急用アカウント。プロバイダー:合意された権限の範囲内での設計、統合、およびテスト。.
スコープ要因
ユーザー、ディレクトリ、アプリケーション、プロトコル、特権アカウント、互換性と移行。ライセンス、物理キー、定常業務は別です。.
確認のための質問
Who confirms arrivals and departures? Which systems must follow? Which access requires business approval?
重要な境界線
Automation depends on HR data quality and available interfaces; not all applications support the same provisioning capabilities.
リカバリと緊急アクセスは、ロールアウト前にテストされます。認証、認可、および特権アクセス管理は、補完的なレイヤーです。.
実際には
具体例.
これらの例は、想定される関与と目標とする成果について説明したものであり、顧客の事例や達成された実績ではありません。.
シナリオ01
A 300-person company shares leaver information through informal messages. Project: define a departure event and tracked actions. Target outcome: controlled revocation, access handover and exception tracking.
シナリオ 02
An employee moves between subsidiaries but retains old access. Project: define roles and mover rules. Target outcome: remove former permissions after checking legitimate transitional duties.
技術と参照コンテキスト
Customer directories, IAM/IGA and connectors; SCIM where available and compatible.
最終的なテクノロジーセットは、相互運用性、ライセンス、アクセス権、および運用要件に基づき、スコープ設定の段階で合意されます。.
コネクテッドサービス
次のステップを構築する。.
これらのサービスはエンゲージメントを補完するものであり、自動的には含まれません。.
会話を始めましょう。
スコープを明確にする。.
このサービスの目的、依存関係、および責任範囲を明確にした上で、納品を提案いたします。.
